Does fire or all risks insurance cover a cyber attack?
No. Malaysian property wordings commonly carry the Property Cyber and Data Exclusion, and it removes cyber loss and data loss in full.
No. Malaysian fire and Industrial All Risks (IAR) wordings commonly attach the Property Cyber and Data Exclusion, published by the Lloyd's Market Association as LMA 5401. It excludes any Cyber Loss, and any loss connected with the loss of use, repair, restoration or reproduction of Data, including the value of the data itself, "regardless of any other cause or event contributing concurrently or in any other sequence." Ransomware, a hacked server or a system outage are outside these policies. Contractor All Risks (CAR) wordings vary between insurers, but the ones we have read carry a cyber or electronic data exclusion as well. Cyber risk needs a policy written for it.
What the exclusion takes out
The clause is short and defines its terms carefully. A Cyber Act is an unauthorised, malicious or criminal act, or the threat or hoax of one, involving any Computer System. A Cyber Incident is wider: it includes any error or omission in operating a system, and any partial or total failure or unavailability of a system. Computer System covers computers, servers, cloud services, phones, networking equipment and backups, whether owned by the insured or any other party.
"this Policy excludes any: 1.1 Cyber Loss; 1.2 loss, damage, liability, claim, cost, expense of whatsoever nature directly or indirectly caused by, contributed to by, resulting from, arising out of or in connection with any loss of use, reduction in functionality, repair, replacement, restoration or reproduction of any Data, including any amount pertaining to the value of such Data"
Two consequences follow. First, it is not only hacking. A staff member deleting the wrong files, or a system failure that stops production, falls inside the definition of a Cyber Incident. Second, the clause states that it replaces any other wording in the policy that bears on cyber loss or data. As written, it does not carve back fire or explosion that results from a cyber act.
Why business interruption cover does not step in
Many owners assume that if systems go down, the business interruption section of an IAR policy will pay for lost income. It will not. In a standard IAR wording, Section II only responds to interruption "in consequence of Damage indemnifiable under Section I." Section I is the physical damage section, and the cyber exclusion is attached to the whole policy, so a loss caused by a cyber act or a data failure is not indemnifiable under Section I. With no qualifying Section I loss, Section II has nothing to attach to. Where the schedule also applies the Property Damage Clarification Clause, it states the point directly: damage to data or software is not physical damage, and business interruption resulting from it is excluded.
The PDPA side: 72 hours from 1 June 2025
An attack that exposes customer or employee personal data now brings a legal deadline as well as a business one. Amendments to the Personal Data Protection Act 2010, with the Commissioner's Guideline on Data Breach Notification, took effect on 1 June 2025. Under section 12B:
- Notify the Personal Data Protection Commissioner within 72 hours of a breach that causes or is likely to cause significant harm.
- Notify affected individuals without unnecessary delay, and no later than seven days after notifying the Commissioner, where that is required.
- Failing to comply is an offence, with a fine of up to RM250,000, imprisonment of up to two years, or both.
None of that response work, from forensic investigation to notifying customers, is recoverable under a fire or IAR policy carrying the exclusion above.
What to check this week
- Look for LMA 5401 in your policy. It is usually printed among the endorsements near the back, under the title Property Cyber and Data Exclusion.
- List what stops if your systems stop. Invoicing, production scheduling, access to drawings, payroll. That list is the exposure your property policy does not carry.
- Read any cyber policy by its insuring clauses. Standalone cyber insurance is the product written for these losses, but what it pays for, and what it excludes, varies between wordings.
Frequently asked
Does fire insurance cover a cyber attack in Malaysia?
No. Malaysian fire and Industrial All Risks wordings commonly attach the Property Cyber and Data Exclusion (LMA 5401). It excludes any Cyber Loss, and any loss connected with the loss of use, repair, restoration or reproduction of data, including the value of the data itself, regardless of any other cause contributing concurrently or in any other sequence.
Does business interruption insurance pay if ransomware stops my operations?
Not under a standard Industrial All Risks policy. Its business interruption section only pays for interruption in consequence of damage indemnifiable under the physical damage section, and the Property Cyber and Data Exclusion is attached to the whole policy. Ransomware downtime therefore has no qualifying physical loss for business interruption cover to attach to.
Is a system failure or staff error covered, or only hacking?
The exclusion is wider than hacking. Its definition of Cyber Incident includes any error or omission in accessing or operating a computer system, and any partial or total unavailability or failure of a system. Both are excluded along with malicious cyber acts.
How quickly must a Malaysian business report a personal data breach?
Since 1 June 2025, section 12B of the Personal Data Protection Act 2010 requires a data controller to notify the Personal Data Protection Commissioner within 72 hours of a breach that causes or is likely to cause significant harm, and to notify affected individuals no later than seven days after that where required. Failing to comply is an offence carrying a fine of up to RM250,000, imprisonment of up to two years, or both.
Fire and IAR policies in Malaysia commonly exclude cyber loss and data loss in full, through the Property Cyber and Data Exclusion (LMA 5401). Business interruption does not step in either, because data damage is not physical damage. With a 72-hour PDPA notification rule now in force, cyber risk needs its own policy, read clause by clause.
Clause references are to fire, Industrial All Risks and Contractor All Risks wordings in use in Malaysia. PDPA references are to the Personal Data Protection Act 2010 as amended, and the Commissioner's Guideline on Data Breach Notification effective 1 June 2025. Your own policy and endorsements can differ. This page is general information, not legal advice or advice on a specific claim.
AY Shield is a licensed insurance advisor based in Penang, Malaysia, serving contractors across Penang Island and Seberang Perai. We specialise in Contractor All Risks (CAR), WIBA and Public Liability cover for CIDB G4–G6 building and civil contractors. Principal Advisor Au-Yang Liang-Hin has over 30 years of commercial insurance experience.
Published 29 September 2026 · Bayan Lepas, Penang